
EC-CouncilCertified Network Defender
Domain 5Objective 2
Network Logs Monitoring and Analysis CND Practice Questions (Page 10)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
47questions here
10free pages
8concepts
Questions 46–47
- 46
A small company needs to collect logs from network devices (routers, switches, firewalls) and Windows servers into a central SIEM. The devices support syslog, and the servers support Windows Event Forwarding. The company has limited budget and no dedicated log-collection infrastructure. Which approach is most appropriate?
Select an answer first - 47
Management asks for a summary of security incidents detected in the last quarter. The SIEM has alert data and incident tickets. What is the best way to produce this summary?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CND
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.